Asean's diversity creates cyber security hurdles

Businesses and governments face an intricate policy and regulatory landscape.

Published Tue, Oct 2, 2018 · 09:50 PM

    THOSE who have travelled across South-east Asia would have experienced its rich ethnic and cultural diversity - the heart of what makes the region so unique. But it is also this diversity that creates a more intricate and challenging policy and regulatory landscape for businesses to operate in and, more importantly, for governments and businesses alike to adopt comprehensive and consistent approaches to cyber security.

    In a world where cybercrime and cyber terrorism are rising at a worrying pace, a united approach to cyber security is increasingly important, especially in the Association of South-east Asian Nations (Asean), whose member states are among the world's most exposed to malware and other cyber threats.

    Various Asean member states are rising to the challenge by creating legal regimes to protect data from cyber attacks and physical security breaches. Take Indonesia for example, one of the world's most vulnerable countries to cyber attacks. Its recently established National Cyber and Encryption Agency (BSSN) is a big step in the right direction, especially in realising key digital economy roadmaps such as Making Indonesia 4.0. It will be important for BSSN to carry out its broad and ambitious mandate through transparent and effective enforcement, in close collaboration with the private sector.

    Vietnam's efforts at establishing a legal framework for cyber and information security are also commendable. However, in implementing its recently enacted cyber security law, Vietnam will need to closely consult with the industry and all stakeholders to guard against the risks of overly rigid interpretations of the law. Other countries in the region, such as Thailand and Malaysia, are also working on comprehensive cyber security legislation.

    As we have experienced first-hand, cyberthreats know no geographic boundaries, and we are all increasingly susceptible to cyber attacks as the region's digital economy grows. During Singapore's International Cyber Week (SICW) in September under the theme "Forging a Trusted and Open Cyberspace", the need for cyber security preparedness, strong digital infrastructure and sound policies was once again thrust into the spotlight, with a greater focus on facilitating multi-stakeholders' dialogues and international cooperation this time round.

    As we enter the last quarter of Singapore's Asean chairmanship this year, what more can the island-state do to strengthen its role as a regional leader in developing and encouraging effective cyber security policies in the region? What legacy do we want to leave behind for the next Asean chair to take over?

    Securing the data at the heart of our modern digital economy is a never-ending effort requiring interoperability and collaboration, as exemplified by the steps that Singapore has taken in the lead-up to SICW.

    CYBER RESILIENCE

    Singapore's landmark Cybersecurity Act, which came into force on Aug 31, 2018, is a timely move to enhance the nation's cyber resilience. However, there are elements of the law, such as the licensing of cyber security service providers and the broad scope of investigative powers afforded to government agencies, that necessitate close consultation with all potentially affected parties. Singapore's acknowledgement that more can be done, especially with respect to industry engagement, was seen in several recent announcements such as the launch of an Asean Cybersecurity Centre of Excellence and a bug bounty initiative to identify vulnerabilities in selected government systems.

    As part of SICW, Singapore also led a third Asean Ministerial Conference on Cybersecurity (AMCC) and pledged on behalf of Asean the commitment of all its leaders to inaugurate work on an international cyber security mechanism - one that will adopt a rules-based approach. As the important work on cyber security continues, Asean leaders will need to ensure that policies are guided by six key principles to truly bolster member states' confidence in tackling cyberthreats.

    Policies should:

    At the end of the day, Asean leaders will need to guard against fragmentation and work towards strengthening cyber security policies that will be relevant for every member state. Leaders will need to recognise long-term repercussions of ineffective policies that can jeopardise economic growth, jobs and investment streams.

    While it remains to be seen whether these Singapore-led cyber security initiatives will be effective in the long run, it would be critical for Asean leaders to take advantage of them and continue to build upon the groundwork that Singapore has laid to bring together a community of multi-disciplinary and multi-national stakeholders to work towards a common goal. To quote Abraham Lincoln, "a house divided against itself cannot stand". This certainly holds true for Asean's approach to cyber security.